Privacy Policy for MenuLens
MenuLens explains the dishes on a menu you photograph. This policy says what we collect to do that, why, who receives it, and your choices.
What we collect
Account. On first launch we create an anonymous account identifier so your scans, dishes and purchases can be attributed without any sign-up. If you choose to create or link an account, we also collect your email address and password, or your Sign in with Apple identity, and an optional display name. The email is used to sign you in and for password-reset, sign-in and email-change messages.
Content you create. The menu photographs you take or import, stored privately so past scans can be reopened; the parsed results (restaurant name, cuisine, venue type, language, currency, and every dish with its explanation, prices, flags and picks); the dishes you like; and your home currency. Photographs may incidentally capture your surroundings; they are processed once per scan, swept if a scan never completes, and removed on deletion.
Your taste profile — spice tolerance, adventurousness, dietary patterns, allergens and custom allergens, texture aversions and loves. This is sensitive: allergens are health information, and dietary patterns such as halal or kosher-style can be religion-adjacent. It is stored so only you can read it, used solely to rank picks and produce advisory allergen and dietary flags, editable any time from the Taste tab, and deleted with your account. The app never clears a dish as safe.
Purchases. Subscription and transaction identifiers, product identifiers and your remaining scan credits. We never see your card details.
Device. Apple-issued device attestation tokens and a per-device attestation key. They enforce the one free scan per device and block forged requests, nothing else; a marker is set on Apple's servers when the free scan is used and persists across reinstalls by design.
Usage. Counts of the scans, photo lookups and profile updates you run, for rate limiting and abuse prevention.
MenuLens does not collect your location, contacts, biometrics, payment card details or an advertising identifier, and contains no analytics, crash-reporting, advertising or cross-app tracking software.
How we use it
We use this information to run the features you use — reading menus, explaining dishes, ranking picks, flagging allergens, finding dish photos, converting prices, keeping your history — to operate your account if you create one, and to manage your subscription and scan credits. We do not sell personal data and do not use it for advertising.
Who receives it
To run the app we use service providers for hosting, database and storage, AI processing of the menu photos you scan, dish photo search, subscription management, and currency exchange rates, plus Apple for purchases. They receive only what's needed to do that job for us and are bound to protect it.
We may also disclose data if the law requires it or in a business transfer, under this policy.
AI processing
When you scan a menu, the app sends the menu photos together with your taste profile (spice tolerance, adventurousness, dietary patterns, allergens, custom allergens, aversions, loves) and your home currency to an AI provider; for subscribers, batches of liked dishes are sent with the same profile from time to time. No name, email, account identifier or device identifier is included. What comes back is the result: each dish extracted and explained, picks ranked against your profile, likely allergens and dietary conflicts flagged, and taste traits suggested from your likes. It is used only to produce your results, never for advertising, and the provider does not use it to train its models.
Your account and deletion
An account is optional; the app works fully without one. Delete your account and data in the app at Settings → "Delete account" ("Erase my data on this device" if you never created an account) → "Delete everything"; for accounts it is also reachable from the subscription screen's footer. This removes your menu photos, then your account and everything tied to it: profile, taste profile, scans, dishes, likes and usage records. Or email support@monarchlabs.app.
Two things are deliberately kept. Purchase records tied to your App Store subscription — not to your name or email — are retained while the subscription is active, to prevent duplicate credits and abuse; our legitimate interest under GDPR Article 6(1)(f) is the basis. The anti-abuse counters and device attestation records, including the free-scan marker on Apple's servers, are kept so the free scan cannot be repeated by reinstalling.
Deleting your account does not cancel an App Store subscription. Cancel it in iOS Settings → your name → Subscriptions.
Retention
Your data is kept while your account is active and removed within 30 days of deletion, backups included, with the exceptions above.
Your rights
Under the GDPR, the CCPA and similar laws you can ask to access, correct, export or delete your data, or object to how it is used. The in-app option covers deletion; for anything else email support@monarchlabs.app and we will respond within 30 days. We do not sell personal data or use it for cross-context behavioural advertising.
Children
MenuLens is not intended for children under 13 and we do not knowingly collect information from them. If a child has used the app, contact us and we will delete their data.
Contact
Changes
Changes are posted here with a new effective date.